CVE-2017-14635: Code Injection
Published Sep 21, 2017
·Updated
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
Affected Software
83 affected componentsFixes available
debian/otrs2
6.0.16-26.0.16-2+deb10u16.0.32-6
OTRS OTRS=3.3.0
OTRS OTRS=3.3.0-beta1
OTRS OTRS=3.3.0-beta2
OTRS OTRS=3.3.0-beta3
OTRS OTRS=3.3.0-beta4
OTRS OTRS=3.3.0-beta5
OTRS OTRS=3.3.0-rc1
OTRS OTRS=3.3.1
OTRS OTRS=3.3.2
OTRS OTRS=3.3.3
OTRS OTRS=3.3.4
OTRS OTRS=3.3.5
OTRS OTRS=3.3.6
OTRS OTRS=3.3.7
OTRS OTRS=3.3.8
OTRS OTRS=3.3.9
OTRS OTRS=3.3.10
OTRS OTRS=3.3.11
OTRS OTRS=3.3.12
OTRS OTRS=3.3.13
OTRS OTRS=3.3.14
OTRS OTRS=3.3.15
OTRS OTRS=3.3.16
OTRS OTRS=3.3.17
OTRS OTRS=4.0.0-beta1
OTRS OTRS=4.0.0-beta2
OTRS OTRS=4.0.0-beta3
OTRS OTRS=4.0.0-beta4
OTRS OTRS=4.0.0-beta5
OTRS OTRS=4.0.0-rc1
OTRS OTRS=4.0.1
OTRS OTRS=4.0.2
OTRS OTRS=4.0.3
OTRS OTRS=4.0.4
OTRS OTRS=4.0.5
OTRS OTRS=4.0.6
OTRS OTRS=4.0.7
OTRS OTRS=4.0.8
OTRS OTRS=4.0.9
OTRS OTRS=4.0.10
OTRS OTRS=4.0.11
OTRS OTRS=4.0.12
OTRS OTRS=4.0.13
OTRS OTRS=4.0.14
OTRS OTRS=4.0.15
OTRS OTRS=4.0.16
OTRS OTRS=4.0.17
OTRS OTRS=4.0.18
OTRS OTRS=4.0.19
OTRS OTRS=4.0.20
OTRS OTRS=4.0.21
OTRS OTRS=4.0.22
OTRS OTRS=4.0.23
OTRS OTRS=4.0.24
OTRS OTRS=5.0.0-beta1
OTRS OTRS=5.0.0-beta2
OTRS OTRS=5.0.0-beta3
OTRS OTRS=5.0.0-beta4
OTRS OTRS=5.0.0-beta5
OTRS OTRS=5.0.0-rc1
OTRS OTRS=5.0.1
OTRS OTRS=5.0.2
OTRS OTRS=5.0.3
OTRS OTRS=5.0.4
OTRS OTRS=5.0.5
OTRS OTRS=5.0.6
OTRS OTRS=5.0.7
OTRS OTRS=5.0.8
OTRS OTRS=5.0.9
OTRS OTRS=5.0.10
OTRS OTRS=5.0.11
OTRS OTRS=5.0.12
OTRS OTRS=5.0.13
OTRS OTRS=5.0.14
OTRS OTRS=5.0.15
OTRS OTRS=5.0.16
OTRS OTRS=5.0.17
OTRS OTRS=5.0.18
OTRS OTRS=5.0.19
OTRS OTRS=5.0.20
OTRS OTRS=5.0.21
OTRS OTRS=5.0.22
Event History
Sep 21, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14635?
CVE-2017-14635 is classified as a medium-severity vulnerability.
2
How do I fix CVE-2017-14635?
To fix CVE-2017-14635, upgrade to OTRS version 3.3.18 or later, 4.0.25 or later, or 5.0.23 or later.
3
What versions of OTRS are affected by CVE-2017-14635?
OTRS versions 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23 are affected by CVE-2017-14635.
4
What type of attack does CVE-2017-14635 facilitate?
CVE-2017-14635 allows remote authenticated users to gain elevated privileges through code injection.
5
Who should be concerned about CVE-2017-14635?
Administrators and users of OTRS versions earlier than the patched versions should be concerned about CVE-2017-14635.